HomeCyber BalkansNorth Korean Hackers Conceal AnyDesk on Victim PCs for Covert Remote Access

North Korean Hackers Conceal AnyDesk on Victim PCs for Covert Remote Access

Published on

spot_img

North Korea-linked cyber actors known as Kimsuky have recently intensified their efforts against organizations in South Korea and Japan through sophisticated spear-phishing campaigns. These operations aim to install and conceal the remote access software AnyDesk, facilitating persistent and interactive access to victims’ systems. This method is particularly concerning as it allows the attackers to conduct their operations while masquerading as legitimate software activity.

The Kimsuky operation employs a combination of techniques, including the use of OneDrive-hosted lures, malicious Windows shortcut files, and advanced scheduled-task persistence. These strategies are designed to maintain a foothold on the victim’s systems by utilizing PowerShell payloads and seeking to harvest email information across various platforms, including Thunderbird, Outlook, and Gmail. The attackers cleverly disguise their weaponized LNK files as seemingly relevant documents in both Japanese and Korean, often relating to current regional events and policy matters.

Upon receipt of a phishing email, when a recipient clicks on the shortcut, it silently executes a hidden command that not only opens a decoy PDF but also initiates the download of a Visual Basic Script (VBE) payload from infrastructure controlled by the attackers. Once the VBE script is executed, it communicates the victim’s MAC address back to the command-and-control server and processes PowerShell commands directly in memory, minimizing detectable traces on the victim’s hard disk while allowing the attackers to modify future payloads at will.

To ensure long-term access persistence, the attackers establish a scheduled task, cleverly named “Chrome_Update,” which is programmed to execute the VBE loader every fifteen minutes. This polling mechanism effectively transforms the victim’s device into a controlled implant, enabling Kimsuky to remotely update scripts via the command-and-control server without the need for sending new phishing emails or attachments.

The PowerShell modules employed in these attacks gather reconnaissance data on the host, including details about installed security products and system specifications. This collected information is then encoded and exfiltrated to the attackers. The campaign that researchers at ENKI WhiteHat monitored was predominantly active in the first half of 2026, during which targets received phishing emails containing deceptive OneDrive sharing links leading to ZIP archives.

For those using Thunderbird, the malware accesses mbox archives, enabling it to extract email content from the inbox as well as from sent messages and store them in EML file format. Similarly, the Outlook collector scours messages sent or received since January 1, 2026, and separates attachments, storing data in the public Music directory, which is ostensibly inconspicuous.

Among the many tactics used, researchers identified an in-memory keylogger that compiled embedded C# code to capture and log keystroke data. However, intriguingly, the logging component lacked its own exfiltration mechanism, implying a separate PowerShell task was responsible for uploading the captured data.

The campaign also involved the deployment of a malicious Chrome extension designed to scrutinize Gmail activity. This extension monitors the compose and reading interfaces of Gmail, capturing details about senders, recipients, and message content, including attachments, before relaying this information back to the attackers. A joint advisory released in 2023 by Germany’s BfV and South Korea’s NIS had previously documented Kimsuky’s use of malicious Chromium extensions to facilitate the theft of Gmail contents after victims had logged in.

What sets this campaign apart is the Kimsuky group’s adept use of legitimate remote management tools as covert backdoors, a tactic that raises significant concerns for cybersecurity professionals. The attackers took advantage of applications like Chrome Remote Desktop and AnyDesk, creating multiple paths of access that are less likely to trigger antivirus alerts since the applications themselves are usually regarded as safe.

The installation of AnyDesk was particularly intricate; it relied on files downloaded from the attackers’ infrastructure, including legitimate executables and various scripts for launching and configuring connections. The scripts established scheduled tasks that would run the AnyDesk loader every five minutes, effectively concealing the software’s activity from victims.

Kimsuky’s operations also involved using fodhelper.exe to bypass User Account Control during the installation of Chrome Remote Desktop. They further bound the remote access services to authentication data supplied by the attackers, signifying a broader operational strategy aimed at creating a resilient administrative presence instead of relying solely on malware.

The observers at ENKI WhiteHat connected this activity to Kimsuky based on geographic targeting, overlapping methods related to Gmail theft, and substantial similarities with previous installation chains involving AnyDesk observed in 2025. Armed with this information, organizations are advised to scrutinize for suspicious scheduled tasks executing unexpected wscript.exe or PowerShell and to monitor Chrome extensions with excessive permissions. By blocking or closely examining OneDrive links from unsolicited emails and keeping an eye on the execution of processes related to AnyDesk, companies can enhance their defenses against such advanced threats.

In summary, the Kimsuky campaign highlights the evolving tactics of cybercriminals and the pressing need for robust cybersecurity measures, underscoring the importance of vigilance and proactive defenses in a landscape marked by increasing cyber threats.

Source link

Latest articles

NIST Highlights Unique Security Risks in Multi-Cloud Environments

The United States government has issued an urgent warning addressing the distinctive cybersecurity and...

Australian Regulations Require Scam Victims to Demonstrate Bank Failures

Fraud Management & Cybercrime, Fraud Risk Management, ...

New Guidance Assists Businesses in Verifying Quantum-Safe Hardware Claims

In an era marked by the rapid advancement of quantum computing, organizations are increasingly...

Google and Bing Search Results Revealed Covert Banking Phishing Pages

Threat actors are increasingly exploiting Google and Bing as conduits for phishing attacks, leveraging...

More like this

NIST Highlights Unique Security Risks in Multi-Cloud Environments

The United States government has issued an urgent warning addressing the distinctive cybersecurity and...

Australian Regulations Require Scam Victims to Demonstrate Bank Failures

Fraud Management & Cybercrime, Fraud Risk Management, ...

New Guidance Assists Businesses in Verifying Quantum-Safe Hardware Claims

In an era marked by the rapid advancement of quantum computing, organizations are increasingly...